Impact
The vulnerability is an IDOR (Insecure Direct Object Reference) in Adam Retail Automation Ltd.'s MobilMen 20T that allows an authenticated user to manipulate a user‑controlled key, bypassing the software’s authorization checks and granting privilege escalation. The flaw is classified as CWE‑639, where improper verification of a user‑supplied key permits operations that should be restricted.
Affected Systems
Affected products include Adam Retail Automation Ltd.'s MobilMen 20T, specifically versions from v3 up through 10072026. Users running any of these builds must verify whether they are within this range to determine if the system is vulnerable.
Risk and Exploitability
This issue carries a CVSS score of 8.8, indicating high severity, and an EPSS score of < 1%, indicating a very low but non‑zero exploitation probability. It is not listed in CISA's KEV catalog. Based on the description, it is inferred that the attacker would need a valid authenticated session; the vulnerability allows an authenticated user to manipulate a key, so the likely attack vector involves exploitation over the network by manipulating legitimate user session data.
OpenCVE Enrichment